Legal

Privacy Policy

Last updated: April 1, 2026

1. Who We Are

Clopinette is operated by MB aiteklabs ("we", "us", "our"), a company registered in the European Union. We act as the data controller for personal data processed through the Clopinette service.

Contact: [email protected]

2. Data We Collect

Account Data

When you sign up via our authentication provider (Clerk), we receive your email address, display name, and profile picture. We do not store passwords.

Conversation Data

Messages you send to Clopinette (via web chat, Telegram, Discord, or WhatsApp) are stored in per-user isolated containers (Cloudflare Durable Objects) to maintain conversation context and memory. Each user's data is logically separated from all other users.

Files and Documents

Files you upload (documents, images) are stored in Cloudflare R2 object storage, scoped to your user account.

Payment Data

Subscription billing is handled by Stripe. We receive your subscription status and plan type but never see or store your full card number.

Usage Data

We track token consumption and request counts for quota enforcement. We do not use third-party analytics trackers or advertising pixels.

3. How We Use Your Data

  • To provide and operate the Clopinette AI assistant service
  • To maintain conversation history and personal memory
  • To process and deliver AI-generated responses
  • To manage subscriptions and enforce usage quotas
  • To send service-related communications (e.g., billing alerts)
  • To detect and prevent abuse or unauthorized access

4. Legal Basis (GDPR)

We process your personal data under the following legal bases:

  • Contract performance (Art. 6(1)(b)) — to deliver the service you subscribed to
  • Legitimate interest (Art. 6(1)(f)) — for security, abuse prevention, and service improvement
  • Consent (Art. 6(1)(a)) — where required, such as optional features

5. Third-Party Processors

We share data with the following service providers, all acting as data processors under appropriate agreements:

  • Cloudflare (USA/EU) — infrastructure: Workers, Durable Objects, KV, R2 storage. Your conversation data is processed within Cloudflare's network.
  • Clerk (USA) — authentication and user management
  • Stripe (USA) — payment processing
  • AI providers (Anthropic, OpenAI, or your own API key) — your messages are sent to AI model providers to generate responses. BYOK users control which provider processes their data.
  • Messaging platforms (Telegram, Discord, WhatsApp) — if you use bot integrations, messages transit through these platforms per their own privacy policies

6. International Data Transfers

Some of our processors are based in the United States. Transfers are safeguarded by Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. Cloudflare processes data at the edge location nearest to you, which may be within the EU.

7. Data Retention

  • Conversation data and memory — retained while your account is active. You can delete your memory and conversation history at any time via the dashboard or by using the /reset command.
  • Account data — retained until you delete your account
  • Payment records — retained as required by applicable tax and accounting law (typically 7 years)

8. Your Rights

Under GDPR (EU/EEA residents)

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability — receive your data in a structured format
  • Object to processing based on legitimate interest
  • Withdraw consent at any time
  • Lodge a complaint with your local data protection authority

Under US Privacy Laws (CCPA / state laws)

If you are a US resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the "sale" of personal information — we do not sell your data
  • Non-discrimination for exercising your privacy rights

To exercise any of these rights, email us at [email protected]. We will respond within 30 days (or sooner where required by law).

9. AI and Your Data

  • Your conversations are not used to train AI models. They are sent to AI providers solely to generate responses for you.
  • Clopinette's personal memory and self-learning features store information only in your isolated user space, not in any shared model.
  • BYOK (Bring Your Own Key) users send data directly to their chosen provider under that provider's terms.

10. Cookies

We use only essential cookies for authentication session management (via Clerk). We do not use advertising, tracking, or analytics cookies.

11. Security

We implement the following security measures:

  • Per-user data isolation via Cloudflare Durable Objects
  • HMAC-SHA256 signed webhooks with anti-replay protection
  • Ed25519 signature verification for Discord interactions
  • All data in transit encrypted via TLS
  • No public-facing administrative endpoints

12. Children's Privacy

Clopinette is not intended for children under 16 (or the applicable age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us for deletion.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the service or email. Continued use after changes constitutes acceptance of the updated policy.

14. Contact

MB aiteklabs
Email: [email protected]
Website: aiteklabs.com